kidlogger.exe

KidLogger

Tesline-Service s.r.l.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MS Shell Services’.
Publisher:
Tesline-service  (signed by Tesline-Service s.r.l.)

Product:
KidLogger

Description:
Control Panel

Version:
5, 6, 11, 1

MD5:
18ec7ed240a12abd34aabf32be3f0c9f

SHA-1:
8f3591006bbc60ebb8cde9911833e49a839821a6

SHA-256:
8a03b6d37c0b2b4b00b8027e5b48eac343561a43b97a7527ee8fa501067cf2c8

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
8/4/2025 12:29:17 PM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
not-a-virus:HEUR:Monitor.Win32.Kidlogger
15.0.2.529

File size:
430.3 KB (440,664 bytes)

Product version:
5, 6, 11, 1

Copyright:
Copyright (C) Tesline-service s.r.l. 2005-2011

Original file name:
KidLogger.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kidlogger\kidlogger.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/17/2010 6:42:13 AM

Valid to:
1/14/2013 8:15:16 AM

Subject:
CN=Tesline-Service s.r.l., O=Tesline-Service s.r.l., L=Chisinau, S=MD, C=MD

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C5A7B63E2

File PE Metadata
Compilation timestamp:
8/2/2012 1:01:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:iTEz01mLyW+yp43zKRlMotSZdLaEpeb5eGUJ85eu3OJfi:iASYwDhV8eJPfi

Entry address:
0x2BAA8

Entry point:
E8, CE, B7, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, B0, B1, 45, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, B0, B1, 45, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.3955

Code size:
276 KB (282,624 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MS Shell Services

Command:
C:\Program Files\kidlogger\kidlogger.exe -m


Scan kidlogger.exe - Powered by Reason Core Security